Vulnerability index

Browse CVEs

226 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

TYPO3 HIGH 7.5
CVE-2026-6553

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be…

Patch available
Fix from $1,950 2026-04-21
TYPO3 HIGH 8.1
CVE-2025-59022

Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether th…

Fix: 10.4.55 / 11.5.49+
Fix from $1,950 2026-01-13
TYPO3 HIGH 7.8
CVE-2026-0859

TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized du…

Fix: 10.4.55 / 11.5.49+
Fix from $1,950 2026-01-13
TYPO3 MEDIUM 6.4
CVE-2025-59021

Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, create, and modify any redirect r…

Fix: 10.4.55 / 11.5.49+
Fix from $1,600 2026-01-13
TYPO3 MEDIUM 6.5
CVE-2025-59020

By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the…

Fix: 10.4.55 / 11.5.49+
Fix from $1,600 2026-01-13
TYPO3 HIGH 8.8
CVE-2025-59017

Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13…

Fix: 9.5.55 / 10.4.54+
Fix from $1,950 2025-09-09
TYPO3 MEDIUM 6.5
CVE-2025-59015

A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, …

Fix: 12.4.37 / 13.4.18+
Fix from $1,600 2025-09-09
TYPO3 MEDIUM 6.5
CVE-2025-59018

Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑1…

Fix: 9.5.55 / 10.4.54+
Fix from $1,600 2025-09-09
TYPO3 MEDIUM 6.1
CVE-2025-59013

An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.…

Fix: 9.5.55 / 10.4.54+
Fix from $1,600 2025-09-09
TYPO3 MEDIUM 6.5
CVE-2025-7900

The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects fema…

Fix: after 8.3.0
Fix from $1,600 2025-07-22
TYPO3 HIGH 7.2
CVE-2025-47941

TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13…

Fix: 12.4.31 / 13.4.12+
Fix from $1,950 2025-05-20
TYPO3 HIGH 7.2
CVE-2025-47940

TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.3…

Fix: 10.4.50 / 11.5.44+
Fix from $1,950 2025-05-20
TYPO3 MEDIUM 5.4
CVE-2025-47939

TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has histori…

Fix: 9.5.51 / 10.4.50+
Fix from $1,600 2025-05-20
TYPO3 MEDIUM 5.3
CVE-2025-47937

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 …

Fix: 9.5.51 / 10.4.50+
Fix from $1,600 2025-05-20
TYPO3 HIGH 8.0
CVE-2024-55924

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…

Fix: 11.5.42+
Fix from $1,950 2025-01-14
TYPO3 MEDIUM 6.5
CVE-2024-55945

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…

Fix: 11.5.42+
Fix from $1,600 2025-01-14
TYPO3 MEDIUM 5.4
CVE-2024-55922

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…

Fix: 10.4.48 / 11.5.42+
Fix from $1,600 2025-01-14
TYPO3 HIGH 8.8
CVE-2024-55921

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…

Fix: 10.4.48 / 11.5.42+
Fix from $1,950 2025-01-14
TYPO3 MEDIUM 5.4
CVE-2024-55894

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…

Fix: 10.4.48 / 11.5.42+
Fix from $1,600 2025-01-14
TYPO3 MEDIUM 6.1
CVE-2024-55892

TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g.…

Fix: 9.5.49 / 10.4.48+
Fix from $1,600 2025-01-14
TYPO3 MEDIUM 5.3
CVE-2024-55891

TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in c…

Mitigation only
Fix from $1,600 2025-01-14
TYPO3 MEDIUM 5.4
CVE-2024-34357

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS…

Fix: 9.5.48 / 10.4.45+
Fix from $1,600 2024-05-14
TYPO3 MEDIUM 5.3
CVE-2024-34358

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS…

Fix: 9.5.48 / 10.4.45+
Fix from $1,600 2024-05-14
TYPO3 MEDIUM 5.4
CVE-2024-34355

TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to…

Fix: 13.1.1+
Fix from $1,600 2024-05-14
TYPO3 MEDIUM 5.4
CVE-2024-34356

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS…

Fix: 9.5.48 / 10.4.45+
Fix from $1,600 2024-05-14
TYPO3 HIGH 7.2
CVE-2024-22188

TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges o…

Fix: 8.7.57 / 9.5.46+
Fix from $1,950 2024-03-05
TYPO3 HIGH 7.1
CVE-2024-25121

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstra…

Fix: 8.7.57 / 9.5.46+
Fix from $1,950 2024-02-13
TYPO3 MEDIUM 6.5
CVE-2024-25118

TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being reflected in the editing forms…

Fix: 8.7.57 / 9.5.46+
Fix from $1,600 2024-02-13
TYPO3 MEDIUM 5.4
CVE-2023-47127

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two diff…

Fix: 8.7.55 / 9.5.44+
Fix from $1,600 2023-11-14
TYPO3 MEDIUM 5.3
CVE-2023-47126

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the login screen of the standalone i…

Fix: 12.4.8+
Fix from $1,600 2023-11-14